Resources
Free tools we actually recommend.
We make no money from anything on this page. It exists because a fair amount of security work does not need a vendor, and telling you that is cheaper for us than being asked why we did not.
Know what you have
Every framework starts here, and it is the control most often marked complete on the strength of an old spreadsheet.
- Nmap
Network and service discovery. Still the baseline after two decades.
- OWASP Amass
External attack surface discovery. Finds the subdomain nobody remembered.
- CISA Known Exploited Vulnerabilities
Patch this list first. It is what is actually being used against people.
Check your exposure
Free checks that take minutes and catch things that show up in real assessments.
- Mozilla Observatory
HTTP security headers, graded with explanations.
- SSL Labs
TLS configuration. A B grade usually means one setting away from an A.
- Have I Been Pwned
Which of your domain addresses appear in breach data. Free for domain owners.
- MXToolbox
SPF, DKIM and DMARC. Most DMARC records we see are still set to none.
Test your own applications
These will not replace an assessment, and running them before you buy one means you are not paying us to find the obvious.
Compliance
Our own, built for defense contractors. Free, no signup.
- The eight CMMC tools
Readiness check, SPRS calculator, CUI identifier, SSP scaffolder, POA&M builder, practice lookup, asset categorizer, flow-down letter.
- NIST SP 800-171 Rev. 2
The source document. Free, and shorter than people expect.
Everything above is someone else's software. The eight CMMC tools we built are free on the same terms: no signup, no email capture, and no pitch attached.
Run these and want a second opinion?
Bring the output. Working from what you already have is a faster start than beginning from nothing.
